Vulnerability Name: | CVE-2011-1265 (CCN-68298) | ||||||||||||
Assigned: | 2011-07-12 | ||||||||||||
Published: | 2011-07-12 | ||||||||||||
Updated: | 2019-09-27 | ||||||||||||
Summary: | The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that (1) were not properly initialized or (2) have been deleted, which allows remote attackers to execute arbitrary code via crafted Bluetooth packets, aka "Bluetooth Stack Vulnerability." | ||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
| ||||||||||||
CVSS v2 Severity: | 8.3 High (CVSS v2 Vector: AV:A/AC:L/Au:N/C:C/I:C/A:C) 6.2 Medium (Temporal CVSS v2 Vector: AV:A/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-94 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2011-1265 Source: CCN Type: SA45165 Microsoft Windows Bluetooth Driver Object Handling Vulnerability Source: CCN Type: Microsoft Security Bulletin MS11-053 Vulnerability in Bluetooth Stack Could Allow Remote Code Execution (2566220) Source: CCN Type: BID-48617 Microsoft Windows Bluetooth Stack 'bthport.sys' Driver Remote Code Execution Vulnerability Source: CERT Type: Third Party Advisory, US Government Resource TA11-193A Source: MS Type: Patch, Vendor Advisory MS11-053 Source: XF Type: UNKNOWN ms-win-bluetooth-code-exec(68298) Source: OVAL Type: Tool Signature oval:org.mitre.oval:def:12094 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |